Bring Your Own Key (BYOK)
Use your own provider keys through Concentrate
Store your provider credentials in Concentrate. Keep calling our unified API, and burn through your existing credits or committed spend.
Provider, masked preview, owner scope, and which requests ran on your key.
Integration
Same API
Credit spend on BYOK
None
Fallback
Automatic
Provider
OpenAI
Request tries your stored OpenAI key first.
Billing
Direct
Provider bills you. Concentrate balance is untouched.
Fallback
Concentrate
If your key fails, Concentrate is automatically tried as a fallback.
New capabilities
What your team gains with Concentrate
Your keys first, Concentrate as backup
Among equal provider candidates, Concentrate tries providers you hold a BYOK key for first. If every stored key fails, the request falls back to Concentrate, then to the next provider in the chain.
No Concentrate rate limits or credit spend
Attempts on your keys skip Concentrate rate limits and do not debit your Concentrate balance. Only your provider's own limits apply, and the provider bills you directly.
Built to be secure
Every key is encrypted with AES-256-GCM. Once you save a key you can never see it again, only a short masked preview to tell your keys apart.
Who Concentrate is designed for
Teams that already hold provider contracts and still want one gateway
BYOK keeps your existing provider billing relationships while Concentrate still handles routing, logs, spend attribution, and fallbacks.
Teams with committed provider spend
Route GPT-5.5, Claude Opus 4.8, and Gemini traffic through keys you already own, without giving up Concentrate routing and logs.
Security and procurement
Keep provider secrets out of your app repos and CI pipelines. Each key lives in one place, encrypted and out of reach, instead of copied across your stack.
Platform engineering
Add a key once in the dashboard. Every request that routes to that provider uses it automatically. No request-body or header changes.
Finance and ops
Provider bills you directly for BYOK traffic. Concentrate still records usage per key so you can see which stored credential served each request.
Bring Your Own Key (BYOK) basics